MapFlow
Tool Comparison

MapFlow vs the Alternatives

The sovereign-secure alternative to failed "lift and shift" migrations. How MapFlow compares to Arcus Spreadsheet Field Mapping and MS Access Datachecker — the tools councils have been forced into when modern, cloud-native ETL was procedurally blocked.

The AI difference: MapFlow's AI Mapping Assistant creates complete, confidence-scored field mappings from a single natural-language request. Reverse-engineering with candidate records achieves 95%+ confidence by comparing actual source↔destination values side-by-side. What takes weeks of manual data discovery is completed in minutes.

MapFlowArcus SpreadsheetMS Access Datachecker
Modern cloud platform versus legacy desktop tooling
Why MapFlow Exists

A Replacement for Arcus Datachecker

MapFlow is the modern replacement for the Arcus MS Access Datachecker. Every difference in the comparison below comes down to one thing: a modern Platform-as-a-Service, versus Microsoft Office. Datachecker is a genuinely capable tool that has served councils well — but it has reached the hard limit of Microsoft Access, an engine first released in 1992. No amount of expert maintenance can move that ceiling; only a change of architecture can.

You're driving around in a modern car — while data migration specialists are being asked to deliver the same journey in a Model T Ford.

Everyone on the council team streams 4K video to the phone in their pocket, asks an AI to draft their emails, and unlocks their front door from another country. Meanwhile, the people trusted with moving millions of citizen records are handed a desktop file format that launched in 1992 — older than the smartphone, the smart speaker, and the streaming service you use every day. Nobody would expect a Model T to win a modern commute. Nobody should expect a 30-year-old file database to carry a modern data migration. MapFlow is simply the modern vehicle.

How long is 30 years in technology?

The Jet/ACE engine that powers MS Access was designed before most of the technology your council relies on today even existed. To grasp just how long ago that is, here are some of the things that happened in the years since Access was built.

1992

Microsoft Access 1.0 ships. Text messages (SMS) are sent for the first time. Most homes connect to the internet over a dial-up modem that screeches for a minute to load a single page.

1995

Windows 95 launches with the Start button. Toy Story — the first fully computer-animated film — hits cinemas. DVDs are introduced.

1997

DVDs go on sale to the public. The first ringtones are sold for mobile phones. Netflix launches as a DVD-by-post service.

1998

Google is founded. The candy-coloured iMac launches. Most people still buy music on CD.

2000

The first camera phone ships. The PlayStation 2 launches and becomes the must-have Christmas gift.

2001

The iPod launches — '1,000 songs in your pocket' was revolutionary. Wikipedia goes online.

2004

Facebook launches — originally only for university students.

2005

YouTube launches. The first video ever uploaded is literally called 'Me at the zoo'.

2006

Twitter launches. The first 'tweet' is sent.

2007

The iPhone launches — the smartphone as we know it did not exist when MS Access's engine was designed.

2008

Spotify launches. The first Android phone goes on sale.

2010

The iPad launches. Instagram launches — and photography has never been the same.

2011

Snapchat launches — photos that disappear.

2014

Alexa and the smart speaker arrive in ordinary homes. You can now pay for coffee with your phone.

2016

Pokémon GO has millions of people wandering the streets chasing virtual creatures in the real world.

2019

People stream entire TV series in 4K on the phone in their pocket.

2020

Video calls become how the whole family — grandparents included — sees each other.

2022

ChatGPT launches — ordinary people start talking to an AI every day, about anything.

The point: the engine Datachecker runs on predates the iPhone, Wi-Fi, Google, cloud computing, and modern AI by decades. MapFlow is built on today's architecture — a browser-native, cloud-hosted PaaS — which is why it can do things Access structurally cannot. That is not a feature gap; it is a generational one.

The Genesis of MapFlow: Rooted in Operational Expertise

Built by a former Arcus data team lead

I engineered MapFlow as a direct response to these persistent public sector infrastructure challenges, drawing on my four years of hands-on experience leading the Arcus data team. Having managed these data transitions firsthand, I purpose-built MapFlow's architecture to eliminate the chronic data integrity risks and generational vulnerabilities inherent to legacy configurations. This platform is the direct evolution of lessons learned on the front lines of UK data migration. It replaces fragile desktop tools with a secure, browser-isolated solution tailored specifically for public sector pressures.

4 years

Leading the Arcus data team

Front-line

Hands-on management of UK council data transitions

Purpose-built

Architecture engineered to fix legacy failure modes

While building MapFlow, the true scale of the systemic gap and the vast potential for a modern solution became completely apparent to me. The architectural difference and security leap that MapFlow offers turned out to be far greater than I ever imagined when I first commenced development. What started as a mission to fix specific network bugs evolved into a complete overhaul of how public sector data can be securely migrated.

The Regression Paradox

How Enterprise IT Went Backwards

Data migrations once went forward — robust enterprise ETL pipelines carried National Highways assets and banking ledgers at scale. They have since been forced backwards, into a 1992-era desktop file format, by procurement frameworks that block modern, secure SaaS on certification technicalities while grandfathering the very tool it structurally cannot pass.

1

THE ENTERPRISE ERA

Sagent & Talend Pipelines

  • High-volume handling
  • Strict schema enforcement
  • Full data lineage
2

THE REGRESSION

Bypassing Vetting with Access

  • "Grandfathered" software
  • Unencrypted local files
  • 1992-era technology ceiling
3

THE SLEDGEHAMMER

MapFlow Zero-Trust PaaS

  • Browser-isolated WASM
  • Automated compliance
  • Modern sovereign ETL

A Historical Timeline of Scale vs. Modern Stagnation

To understand why a modern solution is required, look at how enterprise data was successfully migrated in the past compared to the current reliance on legacy tools.

The Breaking Point

Streetworks Migration

Early encounters with Microsoft Access during critical Streetworks migrations exposed the hard technical ceilings of the Jet/ACE engine. The database could not cope with the relational complexity and transaction volumes, forcing a total abandonment of the GUI tool in favour of raw SQL scripting just to keep the migration alive.

The Enterprise Benchmark

National Highways

When scaling up to massive infrastructure projects, robust enterprise tools were the baseline. Approximately one-third of all National Highways Assets were successfully mapped, validated, and transferred using Sagent Data Flow, which handled high-volume geospatial and asset metadata without a single corruption event.

The Compliance Benchmark

Corporate Banking

In highly regulated banking environments where data lineage and security are legally mandated, the industry standard relied on heavy-duty integration engines like Talend. Security, auditing, and multi-user concurrency were treated as foundational requirements, not optional luxuries.

The Current Crisis: The "Poor Man of IT"

Despite decades of industry progress, many public sector and corporate migrations have actively regressed.

By forcing data teams to use MS Access simply because it is "free and grandfathered" into an old office license, organizations have become the "poor man in IT" — stuck on a 30-year-old technology platform that lacks an upgrade path, has no concept of REST APIs, and is structurally incompatible with modern cloud compliance.

We have entered a bizarre landscape where data specialists stream 4K video on their phones and utilize AI to draft emails, yet are forced to migrate millions of sensitive citizen records using a desktop file format launched in 1992 — before the invention of the smartphone, the smart speaker, or the modern web.

MapFlow was engineered specifically to break this deadlock — delivering the power of an enterprise ETL pipeline inside a secure, sovereign, browser-isolated package. The enterprise era's lineage and governance, restored on a modern PaaS, with zero CLOUD Act exposure.

Era / Paradigm Comparison Matrix

Era / ParadigmCore TechnologyScalability CeilingSecurity & Governance
The Enterprise Era (Asset & Banking Migrations)Sagent Data Flow / TalendHigh-volume data streams (e.g., 1/3 of National Highways Assets).Full enterprise governance, data lineage, and audited transformation blocks.
The Modern Solution (Sovereign Cloud)MapFlowCloud-scale processing with browser-isolated PostgreSQL 16 WASM engines.Zero-Trust Blueprint. TPM 2.0 key binding, AES-256-GCM field encryption, and automated SIEM auditing.
The Modern Stagnation (The Regression Paradox)Microsoft AccessSevere 2GB file limit. Prone to instant network corruption over modern VPNs.Zero. Plaintext storage, no internal user access controls, no audit trail, and direct personal liability for data breaches.
UK Local Government Reorganisation

The LGR Multi-System Consolidation Matrix

LGR forces newly consolidated councils to run four or five conflicting legacy systems under one roof — a workload Microsoft Access structurally cannot consolidate. MapFlow is the answer: a single in-browser WASM staging layer that unifies every source into one Salesforce target.

4 or 5 Legacy Systems
MapFlow WASM Staging Layer
Unified Salesforce Target
Dual-Running Sync Diff Analysis Logs
Operational Requirement
Why MS Access Collapses
How MapFlow UK Solves It Natively
Dual-Running Transition
No dual-running support. Cutovers are forced into high-risk, all-or-nothing legacy switch-offs.
Controlled continuous sync. Uses source databases as masters, auto-resolving target conflicts while maintaining a phased exit trail.
Cross-System Diff Analysis
No change detection. Zero visibility into parallel edits across systems; teams must manually eyeball datasheets.
Automated CDC Diff Reports. Generates row-level snapshot differentials (inserts/updates/deletes) delivered directly to a searchable Document Library.
Audited Record Updates
No change control. Allows ad-hoc, untracked single-user desktop modifications with zero approval gates or audit history.
Immutable Ledger Control. Every modification is staged, second-admin approved, and run inside an audited transaction with a SHA-256 integrity hash.
Live Database Schema Sync
Manual schema recreation. Requires field names to be manually copied from static text or external spreadsheets.
In-Browser Schema Imports. Auto-imports active schemas from live instances (SQL Server, Oracle, Salesforce, Dynamics) and dynamically updates mappings.

The failure record — "lift and shift" is over

The public record shows what bare-bones cloud migrations produce, across every layer of municipal infrastructure.

Finance & ERP

Birmingham City Council

£140m Oracle Fusion overrun, 8,000 launch defects, Section 114 bankruptcy.

Finance & ERP

Hillingdon Council

EY disclaimed audit opinion on Oracle Fusion/EPM implementation.

Planning & Land Charges

Havant & Bracknell

Arcus SaaS go-live with planning history missing; stalled property sales.

Planning archive

Powys County Council

Idox migration collapsed the public register; 'service unavailable'.

Land Charges & GIS

South Oxfordshire & Vale

Planning↔land registry sync broke; manual cross-checking by staff.

Revenues, Benefits & Housing

Norwich City Council

Civica cloud migration abandoned after years of delays; legal settlement.

National oversight

MHCLG (June 2026)

Planning powers stripped from nine councils in one intervention.

Central government

Home Office / NLEDS

Police National Computer migration failures; PAC censure; mega-vendor dependence.

Sovereignty and operational stability are properties of architecture, not of contracts. When councils "lift and shift" data without mapping it first, the database relationships shatter. MapFlow is the inverse — the migration is engineered first, the data is cleansed and mapped before cutover, and sovereign AI learns the estate. Read the full evidence in the MapFlow white paper.

Fully supported Partial / limited Not supported

Field Mapping & Documentation

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Field mapping specification
Visual drag-and-drop canvas with full SQL export
Excel spreadsheet with manual entry; no validation
Not a mapping tool — runs post-load QA only
SQL join & filter definition
Visual join builder; WHERE filters; exports CREATE VIEW
Described in free-text cells; no validation
Access Query Builder — not portable or version-controlled
Field transformations
Per-field expressions, value maps, defaults, pivots — exported as SQL
Written in notes columns; not machine-readable
MS Access SQL/VBA — but compiled tool can't be extended
Source & destination schema definition
Import from live DB, Salesforce, or DDL — in-browser
Requires separate Datachecker Updater app to refresh
Same Updater app — desktop, not in-browser
Mandatory field identification
Imported from source/destination metadata — visible at design time
Tracked manually or communicated separately
Manual report generation required
IDOX Uniform extraction tools
Screen Capture, DB Schema Scraper, PDF Scraper, Uniface Parser
Manual transcription from PDFs and database inspection
No IDOX-specific tooling
No-vendor-lock-in exit strategy (Script Builder)
Script Builder generates a standalone Python or Node runner with the conversion SQL embedded, plus a plain .sql bundle — the client runs the whole migration from the command line with no MapFlow account, no API, no runtime dependency. Exercises the UK GDPR Article 20 right to data portability — no vendor lock-in
No portable exit strategy — mapping logic is locked in spreadsheets and Access forms; no data-portability mechanism
Compiled Access executable — not portable, no standalone handoff, no portability right

AI & Automation

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
AI-first platform design
AI throughout — mapping assistant, profiling, UAT, even this page
~30-year-old stack (Access, Excel VBA) — no AI mechanism
Compiled Access executable — structurally incompatible with AI
AI field mapping suggestions
NLP assistant + confidence-scored mappings + screenshot analysis + learning. AI engine gated behind admin setting (off by default); when on, routes exclusively to RelaxAI (UK-sovereign LLM). Non-AI engine is the zero-exposure default
Mappings entered manually in cells
No AI capability
Reverse-engineering with candidate records
Supply matched source↔destination pairs — AI compares values for 95%+ confidence. Non-AI algorithmic engine also available (zero data shared with AI)
No value-based matching — manual visual inspection
No reverse-engineering capability
Screen Grab → Mapper pipeline
AI generates confidence-scored mappings from captured UI fields + PII + Postgres data
No screen capture or AI generation — weeks of manual discovery
No screen capture or AI mapping
Natural language (NLP) mapping creation
'Map Customers to Account' — produces scored mappings with PII flags and code/value maps
No AI or NLP — manual cell entry
No NLP capability
AI join relationship inference
AI analyses schema to propose join conditions
Manual from source documentation
N/A
AI data quality & PII analysis
Per-field PII/quality scoring; deep scan on Local Table row data
No analysis capability
Validates post-load but does not identify PII
Validation AI Assistant (design-time)
Checks mappings against live SF metadata — required fields, picklists, types, validation rules
Issues discovered during or after load
Pre-load validation only, after data is staged
AI UAT test plan generation
Positive, negative, and edge-case test scripts per mapping
Written manually by the consultant
Data validation checks, not structured UAT plans
Schema import from live database
Auto-imports from SQL Server, Oracle, Salesforce, Access
Field names manually copied from documentation
Manual setup per migration

In-Browser Pipeline Engine (PGLite vs MS Access)

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Transform engine
Real PostgreSQL 16 compiled to WASM — full SQL: CTAS, window functions, CTEs, JSON, regex, typed casts. Identical dialect to the Postgres destination
No engine — Excel is not a runtime
Jet/ACE desktop engine (32-bit lineage), proprietary file format, limited SQL — no window functions, no CTEs
Storage ceiling / corruption
Sandboxed local IndexedDB persistence — PGLite is a per-pipeline staging layer; results push to Postgres and temp tables auto-dispose. No 2GB ceiling, no corruption
N/A
~2GB per .accdb (practical ~1GB before corruption risk); compact-and-repair is a ritual; a flipped bit can lose a weekend
Concurrency
Each browser tab is an isolated WASM Postgres instance — analysts run pipelines concurrently with zero file-lock contention
Shared-drive spreadsheet — merge conflicts common
Single-writer, file-locked — a second analyst blocks the first
Pipeline orchestration (dependency graph)
PglitePipeline entities — ordered steps (mapper/SQL/push/drop), declared depends_on, topological graph runner with parallel waves, per-step run log, drag-to-reorder, auto-dispose
No pipeline concept — manual
Manual query-naming regime encodes run order in names; no topological runner, no per-step log, no isolated re-run of a failed step
Version control / diffability
Pipeline + MappingConfig + SqlSnippet entities are structured records — diffable, exportable, restorable, reviewable via Merge Review
Binary spreadsheet — un-diffable; 'versioning' = dated file copies
Binary .accdb — un-diffable; no merge review, no rollback to a specific transform
Deterministic profiler + PII twins
Deterministic PII + profiling run as REAL full-table SQL against loaded PGLite data — exact null % / distinct counts, full-dataset regex PII sweeps (no 25-row sample). Reconciled with the AI twin so agreements auto-accept
No profiling — eyeballed in cells
No deterministic twin — the only 'model' is the operator eyeballing datasheets; PII calls are judgement, not audited
Offline / air-gapped (the one fair win for Access — in theory)
Transforms run in-browser with no server round-trips, but the app shell + auth need a connection on first load. Script Builder exports an offline runner for truly disconnected sites
Spreadsheets work offline but are not a transform engine
Access runs offline on a single laptop in principle — but Arcus doesn't ship it that way. The .accdb is handed to the council's InfoSec / IT team, who place it on a network share (for access control, backups, AV scanning) and remote consultants open it over SMB — frequently over a VPN from home or another site. That is the worst-case workload for the Jet/ACE engine: chatty block-level I/O over a high-latency VPN link, file-lock contention between concurrent users, and corruption on a dropped VPN mid-write. Compact-and-repair becomes a daily ritual. The 'fair win' only holds for one analyst on a disconnected laptop; in the actual Arcus deployment pattern — network share + VPN — it performs terribly

AI Learning & Fine-Tuning

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Day-one learning capture
Every accepted mapping, PII label, purpose statement, and screenshot correction is captured as a de-identified training pair (field names/types/labels only — never raw citizen values). Idempotent capture job, re-run any time
No capture mechanism — mappings live in cells and leave with the consultant
No capture mechanism — no learning accumulates
Fine-tune unique LoRA adapters
Four task-specific adapters (field mapping, PII classification, schema→purpose, screenshot detection) fine-tuned via QLoRA on MapFlow's proprietary corpus. Export JSONL (unsloth / axolotl / llama.cpp format). Adapter is ~30-100MB, never published
No AI, no fine-tuning — structurally impossible on a 30-year-old stack
No AI, no fine-tuning — Jet/ACE and VBA predate modern AI entirely
Proprietary data moat
The base model is public (anyone can download Llama 3); the adapter is not — it encodes thousands of council-migration patterns only MapFlow holds, on a sovereign host that never publishes it. The longer it runs, the wider the gap
No proprietary corpus — mappings are tribal knowledge in spreadsheets
No corpus — no compounding advantage
Sovereign training + serve host
Train and serve on Civo Project Mercury (client-provisioned UK LON1 GPU) or local Ollama on a maxed M-Max Mac / workstation (fully air-gapped). Adapter, key, and prompts all on the same host — MapFlow backend is relay only
No AI substrate — no training or serving path exists
No AI substrate — Access has no REST surface, no LLM concept, no upgrade path

Governance & Collaboration

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Version control
Semantic versioned snapshots — restore any previous state
Files get overwritten; no change history
No versioning
Audit trail
Full change history and execution logs per mapping
No audit trail — knowledge leaves with the consultant
No audit trail
Formal sign-off workflow
Business, Consultant & PM sign-off per version; Client Management Report PDF
Informal — email or verbal confirmation
No sign-off capability
Audited data-change control (no hot fixes)
Every production data correction is staged, second-admin approved, then applied overnight inside an audited transaction with an immutable ledger + SHA-256 integrity hash and one-click revert. Direct edits are disabled. Fixes are gated on a successful overnight SF→Postgres copy so they can't be overwritten, and optionally dual-push to Salesforce to keep both systems in sync
Direct edits to the spreadsheet or ad-hoc SQL — no staging, no approval, no revert, no audit ledger
No change-control workflow — single-user desktop edits with no audit trail
Risk & issue log
Integrated risk register linked to mappings, tables, columns
Tracked in a separate spreadsheet or not at all
N/A
Multi-user team collaboration
Cloud-based; multiple consultants work in the same project
Shared drive spreadsheet — merge conflicts common
Single-user desktop application
Merge review & version comparison
Diff existing vs AI-generated; accept/decline per change with audit trail
No comparison — versions overwritten
No version comparison
Tagging & filtering of field mappers
Structured tags (category + sub-type + color); dashboard status tabs + multi-tag filter
All mappings in one flat spreadsheet
No tagging or filtering
Per-mapping confidence validation
Reviewers override AI scores with name, timestamp & notes
No confidence scoring
No confidence scoring
Slack & Microsoft Teams bot integration
AI auto-replies to @Mapflow mentions in Slack (real-time webhooks) and Teams (channel polling)
No Slack or Teams integration — communication is email/phone only
No collaboration platform integration
In-app support tickets with notifications
Structured tickets with categories, priority, Slack notifications, and admin chat — replaces email chains
Support requests via email or phone — no tracking, no audit trail
No in-app support system
Connector onboarding conversations
Structured conversations for secure credential exchange with automatic purging on close — credentials never linger
Credentials shared via email or chat — no purge, no audit
No connector onboarding system

Salesforce Integration

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Live Salesforce object schema import
Imports fields, picklists, validation rules, record types, triggers — in-browser
Datachecker Updater reads SF metadata — requires separate Windows app
Same Updater app — desktop, not in-browser
Salesforce validation rules awareness
Imports live validation rules — visible at design time
Not synced by Updater — must be reviewed manually in SF Setup
Not synced — must be verified manually before load
Salesforce trigger awareness
Imports Apex trigger metadata per object
Not surfaced — must be identified and disabled manually
Not surfaced — must be identified and disabled manually
Salesforce picklist value mapping
Live picklist & dependent picklist values per object per record type
Values copied manually into the spreadsheet
Some checking against static definitions
Document table identification & audit
AI scores tables for document storage; SZDD decompression, OLE2 CLSID detection, case-sensitivity
Arcus internal Document Load tool only — not standalone
No document table assessment capability
Built-in Salesforce loaders
ContentVersion (2 GB streaming), ContentNote, Table Data, Document Relink — all built-in. Hybrid SharePoint + Public_Share__c loading
Arcus internal tools only — not standalone
No document uploading capability
Additional / custom staging tables
Local Tables + Postgres staging with environment tiers + Table Loader with DT_ID writeback
Not supported
Does not support additional tables
End-to-end overnight data transfer scheduling
Entire pipeline scheduled overnight: source refresh → SQL transformations → Salesforce load — all unattended, no browser tab, with failure review and admin alerts
Each step requires manual consultant intervention — no scheduling
No scheduled or unattended capability — single-user desktop
Pre-load SF metadata toggle
Auto-disables validation rules, Apex triggers & flows before load; restores after — snapshot-backed
Must be disabled manually in SF Setup and re-enabled by hand afterward
No metadata toggle — rules and triggers cause load failures
Failure review & admin notification
Per-batch log with drill-down per-record errors; admin email on failure with sample errors
Errors lost in Data Loader logs — no structured review
Logs failures but no email alerts or per-record drill-down
Transfer modes (replace / insert / upsert)
Pre-Go-Live: delete previous run's records by SF ID, then insert fresh. Go-Live: insert only. Post-Go-Live: upsert (update existing by SF ID, insert new)
Manual wipe-and-replace only — no tracked SF IDs for targeted deletion
No transfer mode concept — single load approach only
Post-Go-Live delta-only loading
Watermark-based delta sync — only modified rows loaded each night, not the full table
Every load is a full wipe-and-replace — no delta awareness
No delta capability — full reload each time
Dual-side reconciliation (source vs Salesforce)
Detects SF-side edits via SystemModstamp; classifies source-only, SF-only, and conflicts; report saved to Document Library + emailed
No change detection — no visibility into parallel edits
No reconciliation — post-load QA only
Controlled dual-running transition support
Source as master; conflicts auto-resolved in favour of source; full audit trail; phased exit criteria — see Dual Running Guide
No dual-running support — legacy switch-off is all-or-nothing
No dual-running capability
Cloud data warehouse (Postgres)
Environment-tiered schema copies, data staging, CRUD viewer, transformation scheduler
No cloud infrastructure — spreadsheet and Access files only
No cloud staging — 2GB local file limit
Browser-based deployment
Cloud UI in any browser; on-prem DBs need a lightweight local proxy
Excel via shared drive — no version control
Requires local Windows client application

Data Quality & Migration Timing

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Catches issues at design time
PII, quality flags, and mapping gaps identified before data moves
Relies on consultant experience; no automated checks
Pre-load validation only — after data is staged in the tool
Pre-migration data profiling
AI profiles live source tables for null rates, cardinality, PII, quality
No profiling capability
Does not profile source data
Pre-load validation checks
Execution logs and validation rules; designed to catch issues before load
No automated validation before load
Core strength — validates staged data against SF rules before SFTP send

Training & Onboarding

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Role-based training environment
Four role tracks with hands-on exercises, dummy data, and 13 sandbox modules
Learn from colleagues and tribal knowledge
Learn by trial and error on live data
Guided migration flow walkthrough
Interactive 14-step lifecycle diagram — each step links to the real screen
Process documented in PDFs or verbal handovers
No guided workflow
PM dashboards & go-live readiness
Sandbox Sync Dashboard with KPIs, progress bars, error messages, and retry actions
Progress tracked manually in separate spreadsheets
No project management visibility

Document Loading Workflow

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Document loading process
Direct pipeline: source → Salesforce ContentVersion. No SFTP, no intermediate steps
Multi-step: extract → decompress → SFTP → metadata entry → load. Internal tool only
Not designed for documents — requires separate Arcus Document Load tool
Source-to-destination latency
Real-time streaming. No staging delays or SFTP wait times
Multi-step handoff — days to weeks depending on volume
N/A — out of scope
Metadata configuration location
Configured where source is defined — no context switching
Separate Datachecker tool — requires manual re-entry
N/A
Eliminate manual SFTP operations
No SFTP — files never leave source until streamed to Salesforce
SFTP transfer mandatory — adds overhead, cost, and risk
N/A
Pre-upload document compression (Local Proxy)
Open-source toolchain (pdfsizeopt, Ghostscript, jpegoptim, optipng) runs on the Local Proxy inside the council network — PDFs up to 90%, images 70%+. Eliminates the Salesforce Storage Tax with no third-party sub-processor in the data path
Documents uploaded at original size — Storage Tax billed in full, forever
No document compression
Hybrid SharePoint / Arcus document loading
Per-upload route to SharePoint (~£0.16/GB) linked via Public_Share__c, or direct to ContentVersion — copy_flag decides per document
No SharePoint integration — all documents stored in Salesforce at premium storage rates
No SharePoint integration
Net cost to project (document storage)
Local Proxy compression + SharePoint hybrid savings offset the Mapflow licence — effectively £0 net cost to the project
Salesforce file storage at premium per-GB rates — no offsetting savings (the Salesforce Storage Tax)
No storage cost strategy

Infrastructure & Scalability

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Geospatial coordinate handling (BNG → Lat/Lng)
Native BNG → WGS84 conversion built-in
No BNG conversion; requires manual external calculation
No native BNG conversion; Oracle pass-through only (not available on SQL Server)
Large dataset processing (>2GB)
Cloud-based execution; no local memory constraints
N/A — spreadsheet is not a runtime
~2GB practical ceiling for MS Access; requires manual batch splitting
Late schema change handling
Re-sync Salesforce schema in-browser; mappings update automatically
Updater app can refresh — requires re-running and redistributing
Updater can refresh — new objects may need developer intervention
Automated database maintenance
Cloud infrastructure handles optimization automatically
N/A — spreadsheet is not a database
MS Access requires periodic Compact & Repair
SQL Server file export & RTF extraction
AI-powered File Exporter + RTF Extractor (SQLite/Excel/Access/CSV output)
Arcus internal Document Load tool — not standalone
No file export or RTF extraction
Change-data-capture (CDC) diff reports
Snapshot differencing with row-level inserts/updates/deletes; email delivery + Document Library
Every sync is full wipe-and-replace with no change visibility
No CDC capability
Document Library — stored reports
Central repository for CDC diffs, management reports, audit reports — searchable from any machine
Ad-hoc files on local machines
Reports generated locally, not shared
Suitable for weekend go-live cutover
Cloud pipelines, parallel execution, automated schema sync
Lack of automation adds operational risk
Sequential processing and size limits add complexity to tight windows

Data Isolation & Sovereignty

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
CLOUD Act exposure
Zero CLOUD Act risk. The only US-parent platform in the data path (Base44) carries ciphertext in volatile memory only — never persists client data. The staging database is a UK-sovereign cloud (UK-registered, UK-owned, no US operations), bound only by UK domestic law. A US production order returns app metadata only — never plaintext citizen data
No data-isolation architecture — spreadsheets on shared drives with no sovereignty boundary, full exposure wherever they sit
Local desktop .accdb files with no sovereignty model — data sits wherever the laptop sits
UK-sovereign encrypted staging database
Citizen data is staged in a UK-sovereign cloud Postgres database. Every PII value is AES-256-GCM encrypted before it reaches the database, so the database itself only ever holds ciphertext — encrypted in the UK, owned by a UK-only entity outside US jurisdiction
No staging database — data sits in spreadsheets on shared drives with no encryption
Unencrypted MS Access .accdb files on local disks — no database-level encryption
Zero persistence of client data
Zero client data is ever persisted on the US-parent orchestration platform. Ciphertext transits volatile memory (RAM) during active pipelines and is never written to Base44 storage. Persistent ciphertext lives exclusively inside the UK-sovereign encrypted database. The orchestration layer is plumbing, not a data store
Persistent spreadsheet records remain on shared drives indefinitely — no ephemeral model
Persistent local file caches — full data footprint on every machine that touches the project
AI residency — UK-sovereign model only
All AI inference routes exclusively to RelaxAI — a UK-sovereign LLM hosted in UK data centres (ISO 27001, Cyber Essentials, SOC 2, opt-out of training). No US AI provider is in the data path. The Sovereign Inference Shuttle keeps the plaintext prompt and LLM key on the Local Proxy; neither ever transits the US-parent platform. Zero CLOUD Act exposure on the AI path
No AI capability — but also no controls. All data handled manually in spreadsheets
No AI capability — no AI-residency posture to assess
Local LLM — nothing but orchestration over the internet
The Local Proxy can point at a locally-hosted Ollama instance (Llama-3 / Phi-3 / Mistral / Qwen) bound to 127.0.0.1 on the operator's own Windows or macOS machine. The proxy decrypts ENC: cells in RAM, fills the prompt template, forwards to the loopback-only model, and returns only the textual answer. NOTHING but orchestration metadata transits the internet — the data, the model, the AES key, and the decrypted prompts all stay local on one host. Cloud UK-sovereign LLM (RelaxAI) is the default; local Ollama is the air-gapped option. Access and spreadsheets have no AI at all, so there is nothing to keep local
No AI capability — nothing to keep local because there is no model
No AI capability — Jet/ACE and VBA predate modern AI entirely; no upgrade path, no LLM concept, no REST surface
Master encryption key custody
Master keys are TPM-bound (TPM 2.0) on the Local Proxy host — cryptographically anchored to the physical hardware via Windows Credential Guard, unsealable only on that motherboard. A raw Master Recovery Key is escrowed to the council's own corporate vault as the break-glass DR path. No key ever reaches the US-parent platform or a password manager
No encryption keys — no key custody model exists. Unencrypted data throughout
No encryption — no keys to custody
Hardware-backed keys — stolen laptop scenario
A stolen laptop yields nothing. The AES-256-GCM key is TPM-bound (TPM 2.0 via Windows Credential Guard; or the macOS Secure Enclave on Apple Silicon) — cryptographically sealed to that exact motherboard and non-extractable. The thief gets the hardware but the ciphertext on disk and the encrypted Postgres rows are unrecoverable without the original chip. PGLite in-browser data holds only AES-256-GCM ciphertext. The same theft that would be a total breach on Access is a dead-end on MapFlow
Stolen laptop = full plaintext breach. Spreadsheets and .accdb files open on any machine with no key to break — the data is the file. One theft = the entire migration dataset and every credential in it
Stolen laptop = full plaintext .accdb PLUS hardcoded DB connection strings in uncompiled VBA modules. Zero hardware binding — the thief opens the file and reads the source-DB password directly. Strictly the worst-case scenario of the three
Data footprint lifecycle
Sandboxed local IndexedDB persistence for ciphertext; plaintext exists only in the operator's volatile RAM for the life of an authenticated session and is discarded on session end — never persisted to any cloud store
Persistent records that remain on shared drives indefinitely with no destruction model
Persistent file caches prone to theft, loss, or unauthorized copying
Untracked copies — the unknown-breach risk
No untracked copies exist. There is ONE audited copy of the data — the encrypted Postgres dataset. The operator's browser holds only transient ciphertext for one session. If a device is lost, you know exactly what it could have held (one session's ciphertext) and when. A breach is identifiable and reportable, not a guessing game
Every consultant who touched the project has a copy on their laptop, the shared drive, a USB stick, and three email attachments — none audited, none inventoried. A stolen laptop is an UNKNOWN breach because nobody knows it ever held a copy. You cannot report a breach you cannot inventory — GDPR Article 33's 72-hour clock starts when you finally notice, if you ever do
The .accdb is distributed by email, RDP, and USB with no register of who holds a copy. A device loss cannot be inventoried, which delays the UK GDPR Article 33 (72-hour) breach notification assessment. This is a documented constraint of un-inventoried file distribution, not an edge case

Access Control & Governance

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Identity & access management (IAM)
Strict RBAC. Integrates with council IdP. Enforces absolute separation of duties. MFA-gated decryption
No programmatic access controls. Shared passwords or links are common
Local file access. Anyone with network share or device access can open the database
Stakeholder least privilege
Compartmentalized views. PMs and non-technical staff get read-only status metrics. Cryptographically blocked from seeing raw PII
Zero least privilege. PMs aggressively campaign for and receive direct master file/S3 access
Single-user access model; no ability to restrict views or isolate sensitive columns
Immutable audit logging
Cryptographic, tamper-proof logs. Every schema match, mapping adjustment, and data transformation permanently logged for GDPR compliance
No change history. Overwritten files mean historical tracking leaves when consultants resign
No internal logging mechanisms. Missing or corrupted files cannot be audited
Credential & onboarding security
Zero-linger credentials. Time-bound, self-purging token handshakes. Credentials never shared via email or chat
Credentials routinely shared via unencrypted emails, chat apps, or plain-text notes
Hardcoded database connection strings inside uncompiled VBA modules

Automated Risk Mitigation

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
PII & special category detection
Automated edge scanning. Real-time identification of personal IDs, financial logs, and enforcement data before transit. Semantic-only by default; deep scan gated
Completely manual. Relies entirely on the consultant noticing sensitive data fields
Does not identify PII pre-load; validates structural syntax only after ingestion fails
Target infrastructure protection
Live validation engine. Continually matches mappings against live Salesforce metadata to block schema-crashing anomalies before deployment
Failures discovered reactively mid-load or post-load, corrupting cloud tables
Post-load staging QA only. Frequently crashes target systems due to datatype rejections
Safe metadata toggling
Snapshot-backed automation. Temporarily disables cloud validation rules and Apex triggers for loading, then deterministically restores them
Manual disabling inside Setup. High risk of human error leaving live cloud rules permanently broken
No metadata toggling capability; triggers and rules frequently cause catastrophic load timeouts

Security & Compliance

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Two-factor authentication (MFA)
TOTP-based; admin-enforced per user; backup codes; 24-hour lockout for non-setup
Windows/network credentials only
Windows authentication only
Automatic session timeout
Configurable (10 min–2 hrs); tracks mouse, keyboard, scroll, touch
Spreadsheets accessible indefinitely once opened
Access app stays open until manually closed
Role-based access control (RBAC)
Admin/user roles; RLS on every entity; multi-project tenant isolation
Shared-drive permissions only
Single-user desktop application
Audit trail & change history
Cryptographic, tamper-proof audit trail and execution logs per mapping version
Files get overwritten; no history — knowledge leaves with the consultant
No audit trail
PII scanning at design time
AI scans schema metadata; Deep PII scan gated behind admin setting (off by default). Non-AI semantic detection is the default — GDPR Article 25
No PII detection — discovered during or after load
Validates conformance but does not identify PII
Data encryption at rest (UK-sovereign cloud DB)
AES-256-GCM encryption on every PII field before it reaches the UK-sovereign Postgres database; the database itself only ever holds ciphertext. Keys are TPM-bound on the Local Proxy — never on the US-parent platform. Blind-index (HMAC-SHA256) search on encrypted columns
No encryption, no SSL, no key management — unencrypted SFTP dumps and spreadsheets
No encryption, no SSL, no MFA-gated decryption
AI data exposure governance (RelaxAI UK-sovereign)
AI routes exclusively to RelaxAI (UK-sovereign, no US operations). Sovereign Inference Shuttle keeps prompts and LLM keys on the Local Proxy — zero exposure to US CLOUD Act. Master kill switch off by default; per-feature admin gates; flagged in weekly InfoSec posture report
No AI capability — no governance framework for data exposure
No AI capability — no governance framework
Backup & disaster recovery (TPM-bound master key)
Encrypted (AES-256-GCM) app-metadata backups; Master Recovery Key is TPM-bound with a raw copy escrowed to the council's own corporate vault. Zero client data in backups — app metadata only. Cross-app restore via the council-held key, no vendor dependency
Manual file copies and shared-drive versioning — no encryption, no key custody
Vulnerable to corruption; no structured backup
Proactive InfoSec posture monitoring
Weekly automated posture runner checks 12+ controls; emails admins on violations; IP/location, connector, MFA, encryption, AI residency checks
No monitoring — no posture checks
No monitoring — no posture checks
Per-access SIEM audit logging (who/where/what)
Every signed-in access logged once per session: who (email/role), when, client IP, and city-level geography (city, region, country, lat/long) + owning ASN/ISP (e.g. ASN 16509 Amazon AWS) and VPN/datacenter/UK-boundary signals. Mirrored as immutable JSON to an S3 SIEM bucket, ingestible by Splunk / AWS Security Lake
No access logging — no record of who opened a spreadsheet or from where
No access logging — local desktop file with no SIEM trail
Proactive Security Threat Register & remedial action log
Live, database-backed register of threats with a full remedial action log (identified → authorised → applied) + per-threat audit trail. Weekly AI structural review (attack-surface mapping, brand protection, compliance benchmarking) AND an event-driven sweep firing immediately on every app publish (code push / deploy, new endpoints, dependency changes) — closes the weekly exposure window for newly-exposed endpoints/credentials
No threat register — no proactive threat monitoring
No threat register — no proactive threat monitoring
Industry standards compliance
NIST SP 800-63B, NIST SP 800-53, ISO 27001, GDPR Art 25 & 30, SOC 2, PCI DSS v4.0, UK GDPR DPIA
No security controls mapping
No security controls mapping

Defensive Posture & Evidence

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Tamper-evident hash-chained attestation ledger
Append-only SHA-256 hash-chained DefensiveAttestation ledger — AI calls, source-table fingerprints, run correlations, and no-telemetry statements are each chained. Any modification to a stored record is detected on re-verification — a fabricated 'MapFlow broke our data' claim is provably wrong against immutable backend logs
No evidence ledger — no way to prove what was or wasn't done. Disputes resolve to he-said/she-said
No evidence ledger — no tamper-detection mechanism exists in a flat .accdb
Off-platform SIEM mirror (survives DB compromise)
Every attestation, access log, call-home and InfoSec violation is mirrored write-once to an Object-Locked S3 bucket in the council's own AWS account (COMPLIANCE mode, 7-year retention). The on-platform chain is tamper-evident; the SIEM mirror is tamper-resilient — an independently-immutable copy survives even a full compromise of the application database
No off-platform mirror — a compromised spreadsheet has no independent surviving copy
No off-platform mirror — a stolen .accdb is the only copy and it is plaintext
Automatic source-table data fingerprinting
ON by default — a source-table content hash (SHA-256) is recorded to the chain automatically before AND after every operation involving a source table (pipeline run, sync, mapping execution), proving MapFlow did not alter council data. Toggling the switch is itself an audited, SIEM-mirrored event
No fingerprinting — no proof data wasn't altered in transit through the spreadsheet
No fingerprinting — no integrity proof against silent modification
Run correlation IDs (cross-checkable against logs)
ON by default — every workflow run / pipeline execution is stamped with a correlation ID chained to the ledger, so a fabricated error-surface claim can be cross-checked against immutable backend logs. Defeats blame-shifting in post-incident reviews
No correlation IDs — no way to tie an observed fault to a specific action
No correlation IDs — faults are unattributable
No-telemetry attestation (heartbeat-only outbound)
On-record proof that analytics telemetry is off and the only outbound network traffic from the local proxy is the license/liveness heartbeat — no citizen data, usage metrics, or PII transmitted. Counters 'you're exfiltrating our data' before it is raised
No telemetry posture statement — spreadsheets have no telemetry, but also no attestation a council can rely on
No telemetry posture statement — and uncompiled VBA can exfiltrate silently with no witness
Audited security-toggle changes (evidence-chained)
Every change to a master security toggle (AI residency kill switch, auto-fingerprinting, correlation-ID minting, cloud-DB proxy kill switch) is itself written to the hash-chained ledger and mirrored to the SIEM — a bad actor cannot silently weaken the evidence posture without a visible, evidence-chained event
No toggle audit — there are no toggles and no audit trail to record their change
No toggle audit — configuration changes are invisible file edits
Weekly InfoSec posture report (violations mirrored to SIEM)
Scheduled weekly posture runner checks 12+ controls (IP/location, connector, MFA, encryption, AI residency, cloud-DB proxy, CLOUD Act kill switch) and emails admins on violations; every violation row is mirrored write-once to the SIEM bucket so a detection cannot be deleted by compromising the app DB
No posture monitoring — no weekly report, no violation detection
No posture monitoring — no checks, no alerting

Financial Sustainability & Risk Liability

Feature
MapFlow
Arcus Spreadsheet
MS Access Datachecker
Upfront license fee
Subscription cost scaled to project requirements
Included in existing Office bundle ('Free')
Included in existing Office bundle ('Free')
Hidden maintenance overhead (the 'labour tax')
£0 / near-zero. Automated database optimization, cloud infrastructure health, and zero deployment footprint
High. Endless manual data entry, version merging, and resolving file conflicts
High. Requires manual batch-splitting for large sets (>2GB) and mandatory, daily 'Compact & Repair' rituals
Network failure & remote-work support
Built-in resilience. Browser-isolated WASM instances prevent network file contention or locks
None. Highly vulnerable to file-overwrite and sync errors over shared drives
Severe risk. High-latency VPNs trigger 'SMB Lease' bugs and packet drops, permanently corrupting database formats
Data reconstruction & corruption costs
£0. Transient, in-memory pipelines backed by automated staging; no raw file data is vulnerable to local corruption
Variable. Prone to silent human errors and manual cell overwrites with no rollback path
Extreme. A single flipped bit or an aggressive corporate antivirus scan locks the file mid-write, destroying a weekend's work
Regulatory breach liability (UK GDPR / ICO)
Fully protected. AES-256-GCM field encryption, strict RBAC, and tamper-evident SIEM logging ensure complete alignment with UK GDPR Articles 25 & 33
Residual risk. Spreadsheets on unsecured local desktops or un-inventoried USBs cannot be inventoried, delaying the Article 33 breach notification assessment
Accountability gap. Plaintext .accdb files lack access logs, encryption, or key management, omitting the UK GDPR Article 32 technical measures. Requires a Strategic Risk Register entry and SIRO sign-off documenting the residual risk under Section 198 of the Data Protection Act 2018

Legacy Desktop File Architecture Constraints — Total Cost of Ownership

Acquisition price is one component of total cost of ownership; residual failure and regulatory costs are borne separately.

A desktop file database bundled into the corporate image carries an acquisition cost of £0. The residual costs — manual data reconstruction, remote-work downtime under documented SMB-over-VPN constraints, and UK GDPR regulatory exposure where Article 32 technical measures are omitted — are not reflected in that line item. Total cost of ownership must account for reconstruction labour, downtime, and regulatory liability, not acquisition price alone.

Acquisition cost

£0 — bundled into the Office image everyone already has.

Residual failure costs

Reconstruction labour, downtime under SMB-over-VPN packet-loss conditions, and Compact & Repair maintenance — billed in staff hours. Baseline: Microsoft KB Error 3343.

Regulatory liability

Plaintext, un-audited citizen data — accountability gap under UK GDPR Article 32 (omitted technical measures) and Article 33 (breach notification). Baseline: UK GDPR; ICO enforcement.

Summary

Key differences in plain language.

MapFlow vs Arcus Spreadsheet

  • No version history — mappings get overwritten with no way to recover previous states.
  • Sign-off is informal — email or verbal, with no traceable audit record.
  • Sharing causes merge conflicts — multiple consultants editing the same spreadsheet.
  • MapFlow replaces this with a structured, AI-assisted, version-controlled platform producing locked, signed-off artefacts.

MapFlow vs MS Access Datachecker

  • Datachecker validates staged data pre-load; MapFlow catches issues at design time, before data is even staged.
  • Datachecker requires a Windows client; MapFlow is fully browser-based.
  • The Updater doesn't sync validation rules or triggers — both must be disabled manually before each load.
  • The tools are complementary: MapFlow designs and governs; Datachecker can be used as a final post-load QA check.

MapFlow vs MS Access (pipeline engine)

  • Access is a 30-year-old single-writer, file-locked, 2GB-ceiling engine that corrupts on network shares — MapFlow's in-browser PGLite is real Postgres 16 with no ceiling, no corruption, and concurrent tabs.
  • Access encodes pipeline order in query names; MapFlow uses a declarative dependency graph with a topological runner and per-step logs.
  • Not even air-gapped in practice: Arcus hands the .accdb to council IT, who park it on a network share and serve it over VPN — the exact workload Access corrupts under. MapFlow's Script Builder exports an offline runner for the one genuinely-disconnected-laptop case Access was built for.
  • MapFlow's deterministic profiler + PII twins run as REAL full-table SQL against loaded data — Access's only 'model' is the operator eyeballing a datasheet.

Iteration Velocity

The speed gap between paradigms directly impacts delivery timelines.

The Arcus Loop — Typical cycle

  1. 1Mismatches between compiled SQL and live Salesforce config trigger batch faults.
  2. 2Resolving bugs requires manually refactoring Access forms, rewriting SQL, rebuilding staging tables.
  3. 3Validation rules and triggers not surfaced by Updater — must be disabled manually before each load.
  4. 4Each schema change restarts the cycle — no automated re-sync.
  5. 5Consultant knowledge held in memory or email, not a version-controlled artefact.

The MapFlow Loop — Faster iteration

  1. 1Salesforce schema changes picked up by re-running import — all fields update automatically.
  2. 2AI suggests revised mappings; consultant reviews and approves.
  3. 3New versioned snapshot created. Previous state preserved and restorable.
  4. 4Sign-off recorded in-platform. Updated mapping ready for next load cycle.

Cutover Recommendation

Weekend Go-Live

For a compressed weekend go-live window, MapFlow is the recommended choice.

  • Large datasets (>2GB) require manual batch splitting — adds complexity during a tight window.
  • Sequential processing means errors discovered late can extend resolution time.
  • Schema changes discovered at go-time require Access expertise; cloud tools re-sync dynamically.
  • Single-user desktop means coordination is manual when multiple issues arise simultaneously.

MapFlow advantages: automated schema sync handles configuration changes in real-time; cloud execution enables parallel processing; browser-based access allows the full team to collaborate during execution.

When to Use Each Tool

The tools serve different phases of the migration lifecycle.

MapFlow

Throughout the project

Use from day one. Design, document, version, and govern all field mappings. Run AI profiling and PII scans. Generate UAT plans. Sign off mappings.

Arcus Spreadsheet

Legacy / transitional only

May be used as a starting point on existing projects. MapFlow can ingest existing mapping logic to accelerate the transition — but new projects should start in MapFlow.

MS Access Datachecker

Pre-load validation

Run to validate staged data before it is sent to Arcus for loading. Complements MapFlow — MapFlow ensures design is correct; Datachecker validates data conforms to SF rules.

SQL Server Tools

File export & RTF extraction

Standalone companion utility for exporting binary files from SQL Server to the file system and extracting RTF field content. Licensed separately — runs alongside MapFlow or independently.

Slack & Teams Bot

Support & communication

AI auto-replies to @Mapflow mentions in Slack channels and DMs. Teams channel polling. Support ticket notifications routed to Slack and Teams. Companion to MapFlow — not a standalone tool.

IDOX Uniform Tools

Schema & doc extraction

Dedicated suite for IDOX Uniform / Uniface migrations: DB Schema Scraper, PDF Documentation Scraper, Uniface Parser, and Screen Capture. Reverse-engineer legacy schemas and UI forms directly into MapFlow mappings.

InfoSec Technical Declarations

Architecture statements for council auditors.

Zero Persistence of Client Data

The US-parent orchestration platform (Base44) never persists client data — not plaintext, not even ciphertext. Ciphertext transits volatile memory (RAM) only during active pipelines and is never written to Base44 storage. Persistent ciphertext lives exclusively inside the UK-sovereign encrypted Postgres database. The orchestration layer is plumbing, not a data store, so a lawful US production order against it returns app metadata only.

Zero CLOUD Act Risk — UK-Sovereign by Design

The staging database and the AI inference layer are both UK-sovereign — UK-registered, UK-owned, with no US operations — bound only by UK domestic law (UK Companies Act 2006 / UK GDPR). A US CLOUD Act production order holds no authority over them. AI routes either to RelaxAI (UK data centres) or — for full air-gap sovereignty — to a local Ollama model on the operator's own machine (no network egress at all); the Sovereign Inference Shuttle keeps plaintext prompts and LLM keys on the Local Proxy in either path. Master keys are TPM-bound to the operator's hardware with a raw copy escrowed to the council's own corporate vault. The net posture: zero client data within US CLOUD Act reach, end to end.

Documented Hardware and Topology Vulnerabilities

Architectural and topological constraints of desktop file databases, each mapped to a verifiable source baseline.

Unmitigated regulatory risks under UK GDPR Article 33

The following are architectural constraints of the Jet/ACE desktop file database engine, not edge-case failures. Each is stated as an objective technical fact alongside its verifiable baseline.

Plaintext file architecture

The .accdb stores all values in plaintext. Without an encryption layer, file access equates to data access. Baseline: UK GDPR Article 32 ('state of the art' encryption requirement).

No application-layer authentication

The .accdb has no native login, RBAC, or session model. Access is governed entirely by host operating-system file permissions, which provide no per-record or per-field granularity. Baseline: NCSC Security Principle 2 (need-to-know access control).

No multi-factor or role-based access control

There is no TOTP, per-user role assignment, session timeout, or GeoIP gate. Windows network credentials are the sole control. Baseline: NIST SP 800-63B (authenticator assurance levels).

No tamper-evident audit logging

The format records no who/what/when. A breach investigation has no evidence base because none was captured. Baseline: NCSC Security Principle 3 (tamper-proof audit trails); UK GDPR Article 30 (records of processing).

Uninventoried copies complicate breach reporting

When .accdb files are distributed by email, USB, and RDP with no register, a lost device cannot be inventoried, which delays the Article 33 72-hour notification assessment. Baseline: UK GDPR Article 33 (breach notification).

No hardware key binding

Without TPM 2.0 or Secure Enclave key custody, a stolen device yields plaintext data with no key to break. Baseline: NIST SP 800-53 SC-12/13 (cryptographic key management and protection).

No cryptographic key lifecycle

There are no keys to rotate, escrow, or phase-destroy, so a per-environment key lifecycle cannot be implemented. Baseline: ISO 27001 Annex A.10 (cryptographic controls).

No AI inference surface

Jet/ACE and VBA predate modern AI; there is no inference path to keep sovereign. MapFlow routes AI to RelaxAI (UK data centres) or a local Ollama model via the Sovereign Inference Shuttle, keeping plaintext prompts and LLM keys on the Local Proxy. Baseline: MapFlow AI Residency configuration.

Format corruption under documented network conditions

The Jet/ACE file format corrupts under SMB lease contention and VPN packet loss. Microsoft documents database inconsistency under these conditions. Baseline: Microsoft Knowledge Base Error 3343 ('Database is in an inconsistent state').

No tamper-evident evidence ledger

A flat .accdb has no hash-chained attestation ledger, no off-platform SIEM mirror, no source-table fingerprints, and no run correlation IDs. Disputes cannot be resolved against immutable backend logs. Baseline: UK GDPR Article 5(2) (accountability).

Baseline summary: encryption at rest, hardware-bound keys, MFA, RBAC, audit trails, a single tracked copy, and a per-environment key lifecycle are the control set a modern migration is required to meet (UK GDPR Article 32; NCSC Principles 2 and 3; NIST SP 800-63B). A desktop file database does not implement these controls by design. The technical control matrix below states each control as an objective fact against its source baseline.

Technical Control Matrix

Objective architectural controls, each mapped to a verifiable source baseline. Statements describe technical facts, not commercial judgements.

Technical Control
MapFlow UK
Desktop File Engines (e.g. MS Access)
Verifiable Source Baseline
Data Encryption Status
Automated field-level AES-256-GCM encryption before persistence; ciphertext only in the UK-sovereign database.
Plaintext file payload; relies on host container-level obfuscation only.
UK GDPR Article 32
Access Control Audit Trail
Immutable, SHA-256 hash-chained logs mirrored write-once to an off-platform SIEM bucket.
Off by default; no decoupled or tamper-evident access tracking.
NCSC Security Principle 3
Multi-User Topology
Isolated browser-tab WASM PostgreSQL 16 engine instances — no shared file locks.
Block-level file-locking over network file shares (SMB protocol).
Microsoft Developer KB Manual
Remote-Access Resilience
Cloud-native execution; no SMB file-lock traffic over VPN links.
SMB protocol over high-latency VPNs produces packet drops that leave .laccdb locks stuck open.
Microsoft KB Error 3343
Storage Ceiling & Integrity
Transient WASM staging with no 2GB ceiling; results push to Postgres and auto-dispose.
~2GB practical ceiling per .accdb with corruption risk under concurrent network writes.
Microsoft Jet/ACE Engine Specification
Cryptographic Key Custody
Master keys TPM 2.0-bound to operator hardware; raw key escrowed to the council vault.
No key material exists — there is no key to bind, rotate, or escrow.
NIST SP 800-53 SC-12/13

No file to mis-deploy

The "we secured it and broke it" failure class, eliminated by design.

The Core Challenge: Securing Legacy Databases on Modern Networks

Local government Information Security (InfoSec) teams face an impossible balancing act when managing legacy file-based databases like Microsoft Access. The traditional security controls required to protect citizen data directly conflict with how these legacy database engines operate.

The Security Imperative

InfoSec teams must enforce zero-tolerance policies for citizen data. This means ensuring robust access control, automated backups, centralized antivirus scanning, and secure remote access via VPNs. Storing data on a single, disconnected endpoint is a major compliance risk.

The Technical Friction

Legacy engines (like Jet/ACE) were designed for local machine environments, not distributed networks. When moved to network shares or accessed over VPNs via Server Message Block (SMB) protocols, the high volume of file-locking traffic often causes severe latency and database corruption.

The Structural Paradox

In this scenario, standard, well-intentioned compliance measures accidentally degrade system stability. The engineering limits of the legacy software force a trade-off between data security and operational viability — there is no deployment pattern in which Access is both approved by InfoSec and performs acceptably, because the two states are mutually exclusive.

Documented Failure Modes — Standard InfoSec Practise vs MS Access

These are not theoretical risks — they are well-documented, vendor-acknowledged failure patterns that recur whenever a file-based database engine meets a modern corporate network.

1. The Official Microsoft Core Flaw — "The SMB Leases Bug"

The Evidence: Microsoft's own official Knowledge Base documentation (Error 3343 / "Database is in an inconsistent state").

The Failure: Microsoft openly documented that when a Windows network file server utilizes "SMB Leases" to optimize network traffic, it completely breaks the Microsoft Access Jet/ACE file-locking protocol.

The Project Failure: When multiple users connect to a shared network drive, the server tries to "lease" chunks of the file to individual laptops to save bandwidth. The moment two users write data simultaneously, the server drops the lease, Access panics, and the database file permanently corrupts. Microsoft's only permanent recommendation for enterprise networks is a clunky server registry hack to disable network optimization entirely.

2. The Remote-Work "VPN Packet Drop" Epidemic

The Evidence: Documented across enterprise IT forums — ServerFault, SuperUser, Microsoft Q&A — tens of thousands of logged project failures matching this exact template.

The Failure: During mass transitions to remote work, companies globally migrated desktop database backends onto secure network file shares so remote teams could connect via VPN.

The Project Failure: VPNs prioritize encryption over continuous data streaming, leading to tiny, normal network packet drops. While a packet drop causes a web page to simply reload, it leaves an Access network file lock (.laccdb) permanently stuck open. This creates an instant "Unrecognized Database Format" error, locking out entire teams and forcing corporate IT to completely scrap remote access projects due to unfixable data corruption.

3. The Enterprise Antivirus "Lockout" Wave

The Evidence: Documented widely by enterprise endpoint management platforms (CrowdStrike, Symantec, Microsoft Defender).

The Failure: Corporate InfoSec mandates require that all shared network drives undergo real-time, continuous antivirus scanning.

The Project Failure: Access is a passive file, not an active database server. Running a heavy query forces massive streams of raw file data across the corporate network. The automated antivirus software flags this sudden, massive file-reading activity as a ransomware signature or malware attack. The security scanner locks the file mid-write to scan it. This sudden security lock forces a hard disconnect while users are saving data, instantly shredding the database file.

The MapFlow Approach: Compliance and Performance by Design

MapFlow resolves this conflict by aligning natively with modern enterprise security standards, removing the need for high-risk workarounds.

  • Native Access Control & Auditability:Identity management, role-based access controls (RBAC), and full audit logging are built directly into the application layer, satisfying governance requirements immediately.
  • Modern Cloud-Native Architecture:Because the platform does not rely on fragile file-sharing protocols, it maintains high performance and data integrity across remote connections and VPNs.
  • Inherent Data Sovereignty:Security boundaries, automated backups, and data residency rules are integrated into the core design, ensuring InfoSec standards are met without compromising the user experience.

UK Regulatory Position — ICO & NCSC

UK regulatory bodies, including the Information Commissioner's Office (ICO) and the National Cyber Security Centre (NCSC), require that personal data processing involves "appropriate technical or organisational measures" (UK GDPR Article 5(1)(f)). Standalone MS Access files often fail these standards, as they lack robust "state of the art" encryption (Article 32), fail to ensure "need-to-know" access control (NCSC Principle 2), and do not provide "tamper-proof audit trails" (NCSC Principle 3). You can read the full guidance on the official websites of the ICO and the NCSC.

Governance Requirements for Sanctioning MS Access

To formally sanction the use of Microsoft Access (.accdb) for sensitive personal data when a compliant alternative exists, the Council must complete the following mandatory internal governance steps, framed against the statutory baseline:

  1. 1Mandatory Legal DPIA: A formal Data Protection Impact Assessment (Article 35 UK GDPR) must be completed, explicitly documenting the technical constraints of the candidate tool regarding encryption, audit trails, and access controls.
  2. 2Formal DPO Consultation: The Council's independent Data Protection Officer (DPO) must review the DPIA and record the residual risk finding, particularly where a viable compliant alternative exists.
  3. 3Corporate Risk Register Entry: The residual risk must be escalated and logged on the Council's Strategic Corporate Risk Register, noting the potential for regulatory fines and loss of public trust.
  4. 4IAO and SIRO Sign-off: The Information Asset Owner (IAO) and the Senior Information Risk Owner (SIRO) must sign the risk acceptance log.
  5. 5Statutory Accountability under Section 198, Data Protection Act 2018: Under Section 198 of the UK Data Protection Act 2018, corporate officers carry personal accountability for organisational data infractions if the technical measures outlined in UK GDPR Article 32 (such as encryption and access control) are omitted. Documenting and implementing those measures is the governance step that discharges that accountability. MapFlow UK aligns directly with these requirements by implementing automated, tamper-evident SIEM logging, AES-256-GCM field encryption, and hardware-bound key custody.

Inconsistency in Vetting Standards: The MS Access Exception

A critical contradiction exists in the Council's current security vetting process.

If Microsoft Access were evaluated as a standalone database software — unbundled from the pre-approved Microsoft Office desktop package — it would be instantly rejected by Procurement and InfoSec.

Standard Access (.accdb) files are not architected to implement the controls required for certification against ISO 27001, SOC 2, or NIST baselines:

No Security Control Alignment

A standalone Access file lacks the structural framework required to map against ISO 27001, SOC 2, or NIST controls. It cannot enforce multi-factor authentication (MFA), role-based access control (RBAC), or automated, tamper-proof audit logging.

Bundled-Image Pre-Approval

MS Access is admitted within the Council through its inclusion in the standard Microsoft Office desktop image, rather than through a standalone security assessment against the controls above. A standalone evaluation against those controls would be the neutral baseline.

Conclusion

Assessing an accredited platform and a legacy desktop file against the same control set is the neutral baseline. Applying a certification barrier to one tool while admitting an uncertified legacy file through the desktop image creates an accountability gap under the UK GDPR Accountability Principle (Article 5(2)).

The Regulatory Deadlock

A structural outcome exists in the current framework. Modern, cloud-native Extract, Transform, Load (ETL) Software-as-a-Service (SaaS) platforms are procedurally blocked where US CLOUD Act exposure cannot be resolved, which routes vendors toward the legacy desktop file database as the default option. Conversely, the cost of developing a sovereign alternative from scratch and achieving independent, third-party audited security accreditations (ISO 27001, Cyber Essentials Plus) is commercially prohibitive for small-to-medium enterprises. The net effect is that an uncertified legacy desktop engine is admitted through the desktop image while accredited cloud-native platforms are blocked on certification grounds — an asymmetry that constrains the adoption of architecturally secure alternatives and leaves residual UK GDPR exposure on the legacy path. Stating this asymmetry is a factual observation of the framework's operation, not a commercial judgement of any vendor.

The Accredited Platform: MapFlow Is Not the Barrier

MapFlow does not run on unvetted infrastructure. The platform-as-a-service (PaaS) layer that hosts, orchestrates, and secures MapFlow — Base44 — is an independently accredited, enterprise-grade platform that has already passed the security audits the framework requires. The accreditation cited as a precondition has, in substance, already been discharged by the platform beneath it.

Because the underlying PaaS carries its own accreditation, the residual certification gap cited against MapFlow is a procedural matter rather than a security concern. The neutral baseline is that an accredited platform and a legacy desktop file should be assessed against the same control set. MapFlow is not the obstacle to citizen-data security; the obstacle is a framework that assesses an accredited platform against controls a legacy file was never asked to meet.

A Replacement, Not a Competitor — Why MapFlow Exists

MapFlow was designed from the outset as a direct replacement for the MS Access Datachecker — not a rival product seeking to displace a weak incumbent. To be clear about the baseline: Datachecker is a genuinely good product. It has served councils reliably for years, and the team behind it built something that works far better than the underlying technology should allow. The problem is not effort or craft; it is that Datachecker is built on a 30-year-old desktop file database engine, and there is no realistic path to materially improve it within that architecture. The ceiling is fixed by Microsoft Access itself, not by the people who maintain it.

Committing to build a modern replacement is, commercially, exceptionally difficult to justify under current conditions. Over the last decade, public sector procurement frameworks have increasingly treated data migration as a low-cost commodity. This approach often overlooks the critical architectural differences between legacy systems and modern, secure data pipelines.

Human Capital and Resource Constraints

The legacy architecture framework creates a significant barrier to talent acquisition and team retention. In the modern technology landscape, skilled data professionals actively prioritize projects that utilize current, cloud-native toolsets to maintain their market relevance. Forcing engineering teams to rely on outdated desktop database structures creates a severe recruitment bottleneck, as qualified practitioners are hesitant to allocate their career development to legacy environments. This challenge is further intensified by procurement models that treat data migration as a low-cost commodity. By deflating the realistic budgets required to secure specialized data talent, public bodies face a continuous cycle of staff turnover and critical skill shortages, directly introducing delivery risks to complex migration projects.

That calculation leaves only boutique, single-operator specialists as the realistic people to develop a tool like this — they are the only ones whose cost base and focus can absorb a multi-year build for a market that procurement has priced as a commodity. Yet those same specialists are precisely the ones structurally unable to clear the full certification stack a procurement framework demands. The result is a market with no natural supplier: the incumbent cannot evolve past its 30-year-old architecture, the scale players cannot justify the build against the collapsed fee, and the specialists who can build it cannot afford the badges. MapFlow exists because of the combination of 30 years of experience — mostly in data transfers, including non-SaaS-based ETL solutions where available — and the extreme velocity of development that can be attained using the PaaS called Base44.

No shared-drive deployment
No VPN file-lock contention
No InfoSec-relocated runtime
Fixed deployment surface

Proactive Security, Not Reactive

MapFlow's security is continuously verified across three tiers — a posture no legacy tool can match.

Roboshadow — Endpoint & App Monitoring

Roboshadow continuously scans operator endpoints and the MapFlow application for vulnerabilities, patch status, and configuration drift — detecting and remediating weaknesses before they can be exploited. MS Access and spreadsheets have no equivalent: a corrupted .accdb file or an unpatched laptop is a silent risk until something breaks.

Independent Security Audit (2026-08-27)

An internal audit identified three MFA findings — plaintext TOTP secrets, base64 backup codes, no rate limiting — all now fixed: secrets AES-256-GCM encrypted at rest, backup codes SHA-256 salted-hashed, 5-attempt lockout with 15-min cooldown. The full audit reference is published on the Independent Security Audit page.

Salesforce vs MapFlow InfoSec

A detailed comparison of MapFlow's sovereign security posture against Salesforce's native security — covering data residency, encryption, CLOUD Act exposure, MFA, audit trails, and access control. See exactly where each platform stands.

Ready to move beyond spreadsheets?

MapFlow replaces the manual spreadsheet workflow with a structured, AI-assisted platform that produces traceable, signed-off mapping artefacts.